HIGH
CVE-2023-21674
CVSS
8.8
KEV
Description
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Summary dbcve.org
This is a Windows Elevation of Privilege vulnerability in the Advanced Local Procedure Call (ALPC) mechanism. ALPC is an inter-process communication facility used extensively by Windows components. An attacker who successfully exploits this vulnerability could gain higher privileges on the affected system, potentially executing arbitrary code in SYSTEM or kernel context.
Mitigation
Apply the Microsoft security update for CVE-2023-21674 to all affected Windows systems. Validate that ALPC-related system components are properly patched and verify the patch deployment across the environment.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
41.81%
Probability of exploitation in next 30 days
98.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.